Kaspersky documented the NightLedger backdoor and ArcBridge and BridgeHead tunneling tools in July 2026.
NightLedger
NightLedger is a Windows backdoor attributed to the Iranian-aligned cyber-espionage actor Mirage Kitten, also tracked as Nimbus Manticore, UNC1549, and Smoke Sandstorm.
Profile source: Mallory opens in a new tabNightLedger
Family profile
NightLedger is a Windows backdoor attributed to the Iranian-aligned cyber-espionage actor Mirage Kitten, also tracked as Nimbus Manticore, UNC1549, and Smoke Sandstorm. It is used in operations targeting organizations in the Middle East, Africa, and South Asia, including aerospace, aviation, defense, telecommunications, government, financial-sector, and small-business entities. NightLedger masquerades as a legitimate Windows component and executes through DLL search-order hijacking. It communicates with command-and-control infrastructure over HTTPS and supports host and user reconnaissance, directory and logical-drive enumeration, process listing and management, process execution, DLL loading, file download, upload, copying, and deletion, screenshot capture, and collection of Windows diagnostic logs. Its command protocol and development characteristics overlap with the actor's previously observed TWOSTROKE backdoor. NightLedger has been used alongside the BridgeHead and ArcBridge tunneling utilities to support covert, long-term access to compromised environments.
Capabilities
- Dll Sideloading
- Exfiltration
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
5 named in public reportingThe article lists "a Windows backdoor called NightLedger" among Nimbus Manticore's recently expanded malware arsenal.
Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.
Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.
Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.
MITRE ATT&CK